Out of Bounds Read Flaw in libssh2 Affects SSH Functionality
CVE-2019-3862

7.3HIGH

Key Information:

Status
Vendor
CVE Published:
21 March 2019

What is CVE-2019-3862?

An out of bounds read flaw in libssh2 prior to version 1.8.1 allows remote attackers to exploit how SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. This vulnerability can potentially lead to Denial of Service attacks or unauthorized reading of client memory data when a compromised SSH server is involved.

Affected Version(s)

libssh2 1.8.1

References

EPSS Score

6% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.